run Windows Server 2012 R2. The domain contains two domain controllers. The domain

controllers are configured as shown in the following table.

The Branch site contains a perimeter network. For security reasons, client computers in the

perimeter network can communicate with client computers in the Branch site only. You plan to

deploy a new RODC to the perimeter network in the Branch site. You need to ensure that the

new RODC will be able to replicate from DC10. What should you do first on DC10?

Run dcpromo and specify the /createdcaccount parameter.

Run the Active Directory Domain Services Configuration Wizard.

Run the Add-ADDSReadOnlyDomainControllerAccount cmdlet.

Enable the Bridge all site links setting.

Correct Answer: C

QUESTION 192

Your network contains an Active Directory forest named contoso.com. The forest contains a

single domain. The forest contains three Active Directory sites named SiteA, SiteB, and SiteC. The

sites contain four domain controllers. The domain controllers are configured as shown in the

following table.

An IP site link exits between each site. You discover that the users in SiteC are authenticated by

the domain controllers in SiteA and SiteB You need to ensure that the SiteC users are

authenticated by the domain controllers in SiteB, unless all of the domain controllers in SiteB are

unavailable. What should you do?

Create an SMTP site link between SiteB and SiteC

Decrease the cost of the site link between SiteB and SiteC

Disable site link bridging.

Create additional connection objects for DC1 and DC2.

Correct Answer: B

QUESTION 193

Your network contains an Active Directory domain named contoso.com. All servers run Windows

Server 2012 R2. The domain contains a domain controller named DC1 that is configured as an

enterprise root certification authority (CA). All users in the domain are issued a smart card and

are required to log on to their domain-joined client computer by using their smart card. A user

named User1 resigned and started to work for a competing company. You need to prevent User1

immediately from logging on to any computer in the domain. The solution must not prevent

other users from logging on to the domain. Which tool should you use?

The Security Configuration Wizard.

The Certification Authority console.

Active Directory Administrative Center.

Certificate Templates.

Correct Answer: B

QUESTION 194

You perform a full installation of Windows Server 2012 R2 on a virtual machine named Server1.

You plan to use Server1 as a reference image. You need to minimize the amount of storage space

used by the Windows Server 2012 R2 installation. Which cmdlet should you use?

Remove-Module

Optimize-VHD

Optimize-Volume

Uninstall-WindowsFeature

Correct Answer: B

QUESTION 195

Your network contains an Active Directory domain named contoso.com. The domain contains a

server named Server1 that runs Windows Server 2012 R2 and has the DHCP Server server role

installed. Server1 has a scope named Scope1. A policy named Policy1 is configured for Scope1.

Policy1 is configured to provide Hyper-V virtual machines a one-day lease. All other computers

receive an eight-day lease. You implement an additional DHCP server named Server2 that runs

Windows Server 2012 R2. On Server1, you configure Scope1 for DHCP failover. You discover that

virtual machines that receive IP addresses from Server2 have a lease duration of eight days. You

need to ensure that when Server2 assigns IP addresses to the Hyper-V virtual machines, the lease

duration is one day. The solution must ensure that other computers that receive IP addresses

from Server2 have a lease duration of eight days. What should you do?

On Server2, right-click Scope1, and then click Reconcile.

On Server1, right-click Scope1, and then click Replicate Scope.

On Server2, create a new DHCP policy.

On Server1, delete Policy1, and then recreate the policy.

Correct Answer: B

QUESTION 196

You have a server named Server1 that runs Windows Server 2012 R2. Server1 has the DNS Server

server role installed. You need to store the contents of all the DNS queries received by Server1.

What should you configure?

Logging from Windows Firewall with Advanced Security.

Debug logging from DNS Manager.

A Data Collector Set (DCS) from Performance Monitor.

Monitoring from DNS Manager.

Correct Answer: D

QUESTION 197

HOTSPOT

Your network contains two Hyper-V hosts that are configured as shown in the following table.

You create a virtual machine on Server1 named VM1. You plan to export VM1 from Server1 and

import VM1 to Server2. You need to ensure that you can start the imported copy of VM1 from

snapshots. What should you configure on VM1?

To answer, select the appropriate node in the answer area.

Hot Area:

Correct Answer:

QUESTION 198

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012 R2. The domain contains two domain controllers. The domain controllers are configured as shown in the following table.

You configure a user named User1 as a delegated administrator of DC10. You need to ensure that

User1 can log on to DC10 if the network link between the Main site and the Branch site fails.

What should you do?

On DC10, run ntdsutil and configure the settings in the Roles context.

On DC10, run ntdsutil and configure the settings in the Local Roles context.

Modify the properties of the DC10 computer account.

Run repadmin and specify /replsingleobject parameter.

On DC10, modify the User Rights Assignment in Local Policies.

Correct Answer: E

QUESTION 199

Your network contains an Active Directory forest named contoso.com. The forest contains a

single domain. The forest contains three Active Directory sites named SiteA, SiteB, and SiteC. The

sites contain four domain controllers. The domain controllers are configured as shown in the

following table.

An IP site link exits between each site. You discover that the users in SiteC are authenticated by

the domain controllers in SiteA and SiteB. You need to ensure that the SiteC users are

authenticated by the domain controllers in SiteB, unless all of the domain controllers in SiteB are